Category: Cyber Threat

A Practical Detection Engineering Framework — 5-stage lifecycle from hypothesis to shipped rule used by modern SOCs · Hypothesis · Data · Logic · Validation · Metrics
0 26
Posted in Cyber Threat

A Practical Detection Engineering Framework Used by Modern SOCs

A five-stage detection engineering framework — hypothesis, data inventory, logic, validation, metrics — with an AWS GuardDuty worked example, YAML rule template, and a failure-analysis playbook for noisy or silent detections.

How to Measure Detection Quality — precision, recall, MTTD, FP rate, SLO — metrics every detection engineer must track
0 22
Posted in Cyber Threat

How to Measure Detection Quality: Metrics Every Detection Engineer Must Track

Precision, recall, F1, alert-fatigue math, ATT&CK saturation and a working scorecard template. The metrics every detection engineer must track — with formulas and a downloadable CSV.

Living-off-the-Cloud Attack Chain Detection — CloudTrail and VPC Flow fusion for malware-free intrusions
0 48
Posted in Cyber Threat

Living-off-the-Cloud Attack-Chain Detection: CloudTrail and VPC Flow Fusion

Living off the cloud | LotC | CloudTrail | VPC Flow | fusion | malware-free

Insider Threat UEBA from VPC Flow Logs — Network-only user behaviour analytics without endpoint telemetry
0 35
Posted in Cyber Threat

Insider Threat Detection from VPC Flow Logs (UEBA Without Endpoints)

Insider threat | UEBA | identity | peer baseline | VPC Flow Logs | behavioral

Kubernetes East-West Attack Hunting from VPC Flow Logs — Pod-to-pod attack detection with namespace and service-mesh awareness
0 39
Posted in Cyber Threat

Kubernetes East-West Attack Hunting from VPC Flow Logs

Kubernetes east-west | pod-to-pod | EKS | namespace boundary | VPC Flow